gnut, a console- and Web-based Gnutella client available for Linux and Windows, is vulnerable to an HTML injection attack. This attack is conducted by sharing a file with HTML embedded into the file name.

The snmpXdmid daemon is an agent that functions as part of the Solstice Enterprise Agent Desktop Management Interface package. It maps Simple Network Management Interface requests to equivalent Desktop Management Interface requests. Versions of snmpXdmid supplied with Solaris 2.6, 7, and 8 have a buffer overflow that can be exploited remotely to execute arbitrary code with the permissions of the root user.

The NetBSD function call sendmsg() can be used by a malicious user to panic the system, causing a denial of service. It has been announced that all versions of NetBSD from 1.3 on are vulnerable to this denial-of-service attack.

It is recommended that users upgrade any NetBSD machines to NetBSD systems dated July 1, 2001, or newer; rebuild the kernel; and reboot the system.

phpBB, a Web-based bulletin board program, has several vulnerabilities that can lead to increased permissions and allow arbitrary commands to be executed on the server with the permissions of the user executing the Web server.

Vulnerabilities have been found in two example applications that ship with Macromedia ColdFusion. These vulnerabilities can be used to view files, create files, and execute commands on the server running ColdFusion. ColdFusion Servers 4.x for Windows, Solaris, HP-UX, and Linux have been reported to be vulnerable. Version 5 of ColdFusion Server has been reported as not vulnerable.

Macromedia recommends that example applications and documentation not be installed on production servers, that the /CFDOCS directory tree be removed from all production servers, and that users read the Macromedia ColdFusion "Best Security Practices" document available from the Allaire Web site.